Skip to main navigation Skip to search Skip to main content

Performance Comparison and Detection Analysis in Snort and Suricata Environment

  • Far East University

Research output: Contribution to journalArticlepeer-review

Abstract

Recently, crimes are cause in the internet by hacking to target one’s and the companies financial. Due to the massive crimes that are caused by digital convergence and ubiquitous IT system, it is clear that the amount of network packet which need to be processed are rising. The digital convergence and ubiquitous IT system caused the IDS (Intrusion Detection System) to process packets more than the past. Snort (version 2.x) is a leading open source IDS which has a long history but since it was built a long time ago, it has several limitations which are not fit for today’s requirements. Such as, it’s processing unit is in single threading. On the other hand, Suricara was built to cover Snorts these disadvantages. To cover massive amount of packets which are caused by digital convergence and ubiquitous IT system Suricata’s have the availability to process packets in multi-threading environment. In this paper we have analyzed and compared Snort and Suricata’s processing and detection rate to decide which is better in single threading or multi-threading environment.

Original languageEnglish
Pages (from-to)241-252
Number of pages12
JournalWireless Personal Communications
Volume94
Issue number2
DOIs
StatePublished - 1 May 2017

Keywords

  • Detection system
  • Network security
  • Snort
  • Suricata

Fingerprint

Dive into the research topics of 'Performance Comparison and Detection Analysis in Snort and Suricata Environment'. Together they form a unique fingerprint.

Cite this